F5-K000150321: Null Pointer Dereference
Published Mar 11, 2025
·Updated
The archivewstringappendfrommbs function in archivestring.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
Affected Software
4 affected componentsFixes available
F5 BIG-IP>=17.1.0<=17.1.2
17.1.3
F5 BIG-IP>=16.1.0<=16.1.5
16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IQ Centralized Management>=8.2.0<=8.3.0
8.4.0
Event History
Mar 11, 2025
Advisory Published
via F5·03:51 AM
Data Sourced
via F5·03:51 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000150321?
The severity of F5-K000150321 is classified as a denial of service vulnerability.
2
How do I fix F5-K000150321?
To fix F5-K000150321, update to the latest patched version of the affected F5 products.
3
What systems are affected by F5-K000150321?
F5-K000150321 affects multiple versions of F5 BIG-IP and BIG-IQ Centralized Management.
4
Can F5-K000150321 be exploited remotely?
Yes, F5-K000150321 can be exploited remotely by attackers via a crafted archive file.
5
What is the impact of exploiting F5-K000150321?
Exploiting F5-K000150321 can lead to a NULL pointer dereference and cause application crashes.